threat-intel CPDLC over ATN-B1 Vulnerabilities A CISA advisory highlights vulnerabilities in the CPDLC over ATN-B1 protocol, which relies on legacy, unauthenticated radio frequency links. These vulnerabilities allow for message injection, denial-of-service conditions… CISA Advisories · Aug 7, 2026 High CVE-2025-71409CVE-2025-71410CVE-2025-71411vulnerabilitythreat-intelsupply-chain
threat-intel Growing Up The Hard Way This article explores the evolving landscape of open source software and the increasing need for commercial support to ensure its long-term viability. The author argues that open source is transitioning into a two-tiered… The Hacker News · Aug 7, 2026 High open sourcemaintenancevendor
threat-intel Cybernox multiplie les revendications de fuites en France Cybernox, a French cybersecurity firm, claims to have leaked sensitive data from several French companies, including BlocTel. They are linking these leaks to a broader campaign targeting Chat Control and criticizing the… ZATAZ · Aug 7, 2026 Medium data-breachfranceprivacy
threat-intel Attacker phished way into US defense supplier's Microsoft 365 account A US defense supplier's Microsoft 365 account was compromised after an attacker successfully phished credentials. The attacker exploited a vulnerability to gain access, highlighting a continuing issue with phishing attac… The Register · Aug 7, 2026 Medium phishingmicrosoftcredential theft
threat-intel Vishing Extortion Group UNC6671 Rebrands After Making Millions UNC6671, an extortion group previously known as BlackFile, has rebranded and continued its operations under multiple names (Redact, Pink, Helix, and Falcon) while targeting sectors like financial services and private equ… SecurityWeek · Aug 7, 2026 High vishingphishingransomware
threat-intel Fuite massive de données RH A French hacker has claimed to have leaked 26GB of sensitive HR data belonging to T2MC, a French industrial cleaning and reception services company, and its subsidiaries. The data includes personal and professional infor… ZATAZ · Aug 7, 2026 High FRhr datadata breachfrench
threat-intel Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails A widespread phishing campaign, leveraging adversary-in-the-middle (AitM) techniques and residential proxies, is targeting organizations across various sectors in the U.S., Canada, and Europe. The campaign, linked to the… The Hacker News · Aug 7, 2026 High USCAEUaitmphishingmicrosoft 365
threat-intel ICE Is Buying Access to Credit Card Records The U.S. Department of Homeland Security’s Intelligence and Operations (I&O) division is reportedly purchasing access to credit card transaction data from a private company, effectively giving them a massive window into… Schneier on Security · Aug 7, 2026 High surveillanceprivacydata-collection
threat-intel AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day An AI-powered research tool, HTTP Terminator, developed by PortSwigger, autonomously discovered several novel HTTP desynchronization techniques, including a zero-day vulnerability in Apache Traffic Server. The tool, usin… The Hacker News · Aug 7, 2026 High CVE-2026-63078UShttpdesyncrqt
threat-intel 'Asimov was right' about rules for robots, says ex-US Cyber Director This article highlights a range of cybersecurity and technology news, including a Microsoft SharePoint vulnerability exploited in the wild, a Russian phishing campaign mimicking Signal support, and acquisitions within th… The Register · Aug 7, 2026 Medium RUvulnerabilityphishingacquisition
threat-intel Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix A 2024 safety recall for Bendix’s EC80 heavy-truck brake controller, initially issued to address memory corruption issues, has been revealed to contain a significant set of vulnerabilities, including a remotely accessibl… SecurityWeek · Aug 7, 2026 High USCAvulnerabilityremote-code-executiondenial-of-service
threat-intel New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables A new attack class, dubbed NatJack, has been disclosed that allows attackers to hijack active TCP sessions and spoof DNS responses by manipulating NAT connection state. The vulnerability exists in both Windows and Linux… The Hacker News · Aug 7, 2026 High CVE-2026-56181CVE-2026-63913nattcp hijackingdns spoofing
threat-intel Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) This article summarizes several cybersecurity vendor announcements and research findings from Black Hat 2026. Key developments include 1Password's research on AI-generated patches and new PAM offerings, Cogent's Mythos-c… SecurityWeek · Aug 7, 2026 High CVE-2026-56181CVE-2026-63913aisecuritythreat intelligence
threat-intel Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access Researchers have discovered a vulnerability in Windows Hello for Business that allows malware running within a signed-in session to leverage the victim's hardware-backed authentication key to gain persistent access to Mi… The Hacker News · Aug 7, 2026 High windowsentria idwebauthn
threat-intel Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th) This article details Atuin, a tool that enhances shell history tracking by storing command history in a SQLite database, providing richer context (directory, duration, exit code, hostname) and end-to-end encryption acros… SANS Internet Storm Center · Aug 7, 2026 Medium forensicsshellhistory
threat-intel TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign The threat actor known as TeamPCP has been active since 2020, engaging in a series of campaigns targeting internet-facing infrastructure and expanding into sophisticated supply chain attacks. Their tactics have evolved s… The Hacker News · Aug 7, 2026 High IRsupply-chainkubernetesreact
threat-intel China launches mysterious probe into security of Palo Alto Networks' products Chinese authorities are investigating the security of Palo Alto Networks' products, raising concerns about potential vulnerabilities and a broader effort to monitor and control cybersecurity technology within China. This… The Register · Aug 7, 2026 Medium CNcybersecuritychinapalo alto
threat-intel Multiples vulnérabilités dans les produits IBM (07 août 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect a wide range of IBM products, including da… CERT-FR · Aug 7, 2026 High CVE-2023-53781CVE-2024-34459CVE-2024-4741vulnerabilitysecuritycybersecurity
threat-intel Multiples vulnérabilités dans le noyau Linux de Debian LTS (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian LTS. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. The affected Debian versions include 11 (Bull… CERT-FR · Aug 7, 2026 High CVE-2022-49803CVE-2022-50114CVE-2023-52494vulnerabilitylinuxkernel
threat-intel How the famed USENIX Security conf is managing a flood of papers in the AI era The USENIX Security conference is grappling with a surge in research papers, particularly those leveraging AI and machine learning. While AI usage is increasing, concerns are being raised about the potential for autonomo… The Register · Aug 6, 2026 Medium USCHRUaimachine learningvulnerability